_STATIC_FILTER

typedef struct _STATIC_FILTER
{
    ULARGE_INTEGER          m_Adapter;
    DWORD                   m_dwDirectionFlags;
    DWORD                   m_FilterAction;
    DWORD                   m_ValidFields;
    DWORD                   m_LastReset;
    ULARGE_INTEGER          m_PacketsIn;
    ULARGE_INTEGER          m_BytesIn;
    ULARGE_INTEGER          m_PacketsOut;
    ULARGE_INTEGER          m_BytesOut;
    DATA_LINK_LAYER_FILTER  m_DataLinkFilter;
    NETWORK_LAYER_FILTER    m_NetworkFilter;
    TRANSPORT_LAYER_FILTER  m_TransportFilter;
} STATIC_FILTER, *PSTATIC_FILTER;

The _STATIC_FILTER structure defines a kernel-mode filtering rule in Windows Packet Filter. Rules can inspect data link layer (Ethernet), network layer (IPv4/IPv6), and transport layer (TCP/UDP/ICMP) headers.

m_Adapter
Specifies the network adapter for which this filter is applied. Set to 0 (QuadPart = 0) to apply to all adapters.

m_dwDirectionFlags
Specifies packet direction for evaluation: PACKET_FLAG_ON_SEND, PACKET_FLAG_ON_RECEIVE, or both.

m_FilterAction
Determines the action taken by ndisrd.sys when a packet matches the filter:

  • FILTER_PACKET_PASS (0x00000001): Passes packet through its normal network processing path.
  • FILTER_PACKET_DROP (0x00000002): Drops the packet immediately in kernel mode.
  • FILTER_PACKET_REDIRECT (0x00000003): Diverts the packet to the user-mode application queue/Fast I/O section.
  • FILTER_PACKET_PASS_RDR (0x00000004): Passes the packet through normal processing AND delivers a copy to the user-mode application (ideal for passive monitoring/sniffing without forwarding latency).
  • FILTER_PACKET_DROP_RDR (0x00000005): Drops the packet from the network BUT delivers a copy to user mode (ideal for security inspection and forensic logging of blocked traffic).

m_ValidFields
Bitmask indicating which layers are evaluated: DATA_LINK_LAYER_VALID (0x01), NETWORK_LAYER_VALID (0x02), TRANSPORT_LAYER_VALID (0x04).

m_LastReset, m_PacketsIn, m_BytesIn, m_PacketsOut, m_BytesOut
Filter statistics tracked in kernel mode. m_LastReset records the timestamp (seconds since Jan 1, 1980) of the last counters reset. m_PacketsIn and m_BytesIn record cumulative incoming packets and bytes that matched this filter; m_PacketsOut and m_BytesOut record cumulative outgoing packets and bytes that matched this filter.

m_DataLinkFilter, m_NetworkFilter, m_TransportFilter
Layer-specific filter definitions specifying MAC, IP, and port/protocol match criteria.

See Also

AddStaticFilterFront, AddStaticFilterBack, InsertStaticFilter, _STATIC_FILTER_WITH_POSITION, _STATIC_FILTER_TABLE, Managing Individual Static Filters